1#!/usr/bin/env node
L2: "use strict";var pU=Object.create;var rg=Object.defineProperty;var fU=Object.getOwnPropertyDescriptor;var mU=Object.getOwnPropertyNames;var hU=Object.getPrototypeOf,gU=Object.proto...
L3: `);let n;for(;(n=wU.exec(s))!=null;){let r=n[1],i=n[2]||"";i=i.trim();let o=i[0];i=i.replace(/^(['"`])([\s\S]*)\1$/mg,"$2"),o==='"'&&(i=i.replace(/\\n/g,`
L4: `),i=i.replace(/\\r/g,"\r")),e[r]=i}return e}function DU(t){let e=NC(t),s=Jt.configDotenv({path:e});if(!s.parsed){let o=new Error(`MISSING_DATA: Cannot parse ${e} for an unknown re...
L5: `).forEach(function(o){r=o.indexOf(":"),s=o.substring(0,r).trim().toLowerCase(),n=o.substring(r+1).trim(),!(!s||e[s]&&S9[s])&&(s==="set-cookie"?e[s]?e[s].push(n):e[s]=[n]:e[s]=e[s]...
L6: `)}getSetCookie(){return this.get("set-cookie")||
CriticalCredential Exfiltration
Source appears to send environment or credential material to an external endpoint.
dist/entry.jsView on unpkg · L1 1Trigger-reachable chain: manifest.bin -> dist/entry.js
L1: #!/usr/bin/env node
L2: "use strict";var pU=Object.create;var rg=Object.defineProperty;var fU=Object.getOwnPropertyDescriptor;var mU=Object.getOwnPropertyNames;var hU=Object.getPrototypeOf,gU=Object.proto...
L3: `);let n;for(;(n=wU.exec(s))!=null;){let r=n[1],i=n[2]||"";i=i.trim();let o=i[0];i=i.replace(/^(['"`])([\s\S]*)\1$/mg,"$2"),o==='"'&&(i=i.replace(/\\n/g,`
L4: `),i=i.replace(/\\r/g,"\r")),e[r]=i}return e}function DU(t){let e=NC(t),s=Jt.configDotenv({path:e});if(!s.parsed){let o=new Error(`MISSING_DATA: Cannot parse ${e} for an unknown re...
L5: `).forEach(function(o){r=o.indexOf(":"),s=o.substring(0,r).trim().toLowerCase(),n=o.substring(r+1).trim(),!(!s||e[s]&&S9[s])&&(s==="set-cookie"?e[s]?e[s].push(n):e[s]=[n]:e[s]=e[s]..
CriticalTrigger Reachable Dangerous Capability
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/entry.jsView on unpkg · L1 101`)),c=a.reduce((y,S)=>y+S.length,0),l=y=>a[y]??[],u=IJ({active:e,renderedItems:a,pageSize:n,loop:r}),d=l(e).slice(0,n),p=u+d.length<=n?u:n-d.length,f=Array.from({length:n});f.splic...
L102: `)}var v_=x(()=>{Pf();hb()});var C_=N((Xbe,w_)=>{var kJ=require("stream"),gb=class extends kJ{#n=null;constructor(e={}){super(e),this.writable=this.readable=!0,this.muted=!1,this.o...
L103: `).length,FJ=t=>t.split(`
L104: `).pop()??"",au=class{height=0;extraLinesUnderPrompt=0;cursorPos;rl;constructor(e){this.rl=e,this.cursorPos=e.getCursorPos()}write(e){this.rl.output.unmute(),this.rl.output.write(e...
L105: `);let a=e+(s?`
...
L116: \v\f\r\x1B !"#\xA5%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_\`abcdefghijklmnopqrstuvwxyz{|}\u203E\x7F\uFFFD\uFFFD\uFFFD\uFFFD\uFFFD
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/entry.jsView on unpkg · L101 1#!/usr/bin/env node
L2: "use strict";var pU=Object.create;var rg=Object.defineProperty;var fU=Object.getOwnPropertyDescriptor;var mU=Object.getOwnPropertyNames;var hU=Object.getPrototypeOf,gU=Object.proto...
L3: `);let n;for(;(n=wU.exec(s))!=null;){let r=n[1],i=n[2]||"";i=i.trim();let o=i[0];i=i.replace(/^(['"`])([\s\S]*)\1$/mg,"$2"),o==='"'&&(i=i.replace(/\\n/g,`
L4: `),i=i.replace(/\\r/g,"\r")),e[r]=i}return e}function DU(t){let e=NC(t),s=Jt.configDotenv({path:e});if(!s.parsed){let o=new Error(`MISSING_DATA: Cannot parse ${e} for an unknown re...
L5: `).forEach(function(o){r=o.indexOf(":"),s=o.substring(0,r).trim().toLowerCase(),n=o.substring(r+1).trim(),!(!s||e[s]&&S9[s])&&(s==="set-cookie"?e[s]?e[s].push(n):e[s]=[n]:e[s]=e[s]...
L6: `)}getSetCookie(){return this.get("set-cookie")||
MediumInstall Persistence
Source writes installer persistence such as shell profile or service configuration.
dist/entry.jsView on unpkg · L1